HIGH 7.5 Go
Improper Authentication in HashiCorp Vault
GHSA-rq95-xf66-j689 · BIT-vault-2021-3282 · CVE-2021-3282 · GO-2024-2509
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the remove-peer raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-3282
- WEB https://github.com/hashicorp/vault/commit/09f9068e22f762da123160233518b440e00bdb3b
- WEB https://discuss.hashicorp.com/t/hcsec-2021-04-vault-enterprise-s-dr-secondaries-allowed-raft-peer-removal-without-authentication/20337
- WEB https://security.gentoo.org/glsa/202207-01
Ready to move
Start Securing
Free, no credit card | First findings in minutes